Compliance services for Australian organisations
Every engagement is delivered by a senior practitioner, fixed-price, with audit-ready evidence at every milestone — inside your existing Microsoft 365 environment, on Checkpoint, our own console included in the engagement. No third-party platform, no junior staff, no surprises.
- Fixed-price delivery
- Microsoft 365 native
- Senior-led
- All major frameworks
Not sure where to start?
Answer three questions. Get your framework.
Frameworks we deliver
Seven frameworks. One evidence set. Zero duplicated effort.
Every framework is delivered with the same methodology and evidence infrastructure — so when you need more than one, the work overlaps rather than duplicates. Select a framework to see how it runs.
Prefer a quick static guide?
Most organisations come to us with a specific trigger — a customer requirement, a contract condition, an insurer question, or a failed audit. Use this as a guide, or book a free 30-min call and we'll tell you exactly what you need.
→ Essential Eight uplift — assessed, implemented to ML2, evidenced.
→ Essential Eight assessment first, then targeted uplift on the gaps they care about.
→ ISO 42001 — model inventory, risk assessments, human oversight, audit-ready evidence.
→ ISO 27701 — DPIAs, ROPAs, data rights workflows, built on top of ISO 27001.
→ DISP / ISM / IRAP — mapped to your Microsoft E5 environment.
Need more than one? Most mid-market programmes combine 2–3 frameworks — we scope them together so the work overlaps rather than duplicates.
All services
ISO 27001
The baseline certification most enterprise, government, and procurement panels require. Gap analysis, risk treatment, SoA, and audit-ready evidence — all automated in Microsoft 365.
Essential Eight
Australia's baseline cyber security framework — all eight controls assessed, implemented, and evidenced to ML2. Fixed-price, milestone-gated, Microsoft 365-native.
IS18 (QGEA)
IS18:2018 delivered as what it actually is — an ISO 27001-aligned ISMS plus Essential Eight, plus QGISCF classification, CSU incident reporting, and the accountable officer's 30 September annual return. Everything stays inside your own tenant.
RFFR (Right Fit For Risk)
Right Fit For Risk for Employment Services providers — the full ISM Statement of Applicability (989 controls + 7 program-deed obligations) delivered on an ISO 27001 ISMS with Essential Eight uplift. Nearly a third of the SoA assessed automatically from your Microsoft 365 tenant.
ISO 42001
Model inventory, AI risk assessments, human oversight, and monitoring — built inside your existing Microsoft 365 stack. Aligned to the Australian AI Safety Standard and EU AI Act.
SOC 2 Readiness
Trust Services Criteria mapped to your systems. Type I and Type II readiness with reusable, automated evidence that unlocks US and global enterprise contracts.
ISO 27701
Extends ISO 27001 into privacy. DPIAs, ROPAs, data rights workflows, and third-party privacy risk — streamlined inside Microsoft 365 without a third-party platform. Aligned to the Australian Privacy Act.
DISP / ISM / IRAP
Defence Industry Security Programme, Information Security Manual, and IRAP readiness. Map your existing Microsoft E5 stack to ASD and ISM requirements and get government panel-ready.
APRA CPS 234
Mandatory for APRA-regulated entities and evidenced by their providers. All 24 requirements, a systematic control testing program, and both notification clocks — cross-mapped to ISO 27001 so nothing is built twice.
NIST CSF
Align to NIST CSF (Identify → Protect → Detect → Respond → Recover) — mapped to ISO 27001 and Essential Eight so work overlaps rather than duplicates.
Not sure where to start?
A free 30-minute call will tell you which framework fits your situation, what the fastest path looks like, and what it's likely to cost. No obligation.